A Robust Integrity Reporting Protocol for Remote Attestation
Frederic Stumpf, Omid Amirhamzeh Tafreschi, Patrick Röder, Claudia Margot Eckert · 2006
Abstract. Trusted Computing Platforms provide the functionality of remote attestation, i.e. attesting the configuration and status of a system to a remote entity. Remote attestation hereby proves integrity and au-thenticity of system environments. This is crucial for policy enforcement, which in turn is needed in many usage scenarios, e.g., DRM. However, applying remote attestation solely allows masquerading attacks. These attacks are possible since the concept of remote attestation does not provide any means for establishing secured communication channels. In this paper we describe this kind of attacks against protocols for remote attestation and present a protocol for preventing masquerading attacks. 1